Tagged “ghsa”
CVEs tagged ghsa, newest first.
3917 CVEsRSS
CVE-2025-66471High· 7.5urllib3 is a user-friendly HTTP client library for Python
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large H…
CVE-2025-37727Medium· 5.7Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
CVE-2025-9566High· 8.1There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…
CVE-2025-58048Critical· 9.9Paymenter is a free and open-source webshop solution for hostings
Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive…
CVE-2025-71348High· 8.1Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
CVE-2024-52980Medium· 6.5Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2024-38819High· 7.5PoCSpring Framework Path Traversal vulnerability
Spring Framework Path Traversal vulnerability
CVE-2024-58351HighFlowise OverrideConfig security vulnerability
Flowise OverrideConfig security vulnerability
CVE-2024-9355Medium· 6.5A vulnerability was found in Golang FIPS OpenSSL
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false posi…
CVE-2024-39896High· 7.5Directus Allows Single Sign-On User Enumeration
Directus Allows Single Sign-On User Enumeration
CVE-2024-38355Medium· 7.3PoCsocket.io has an unhandled 'error' event
socket.io has an unhandled 'error' event
CVE-2023-41052Medium· 5.3incorrect order of evaluation of side effects for some builtins
incorrect order of evaluation of side effects for some builtins
CVE-2022-39135Critical· 9.8Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack
Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack
CVE-2022-23064High· 8.8snipe-IT vulnerable to host header injection
snipe-IT vulnerable to host header injection
CVE-2022-0577Medium· 6.5Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
CVE-2020-10571Critical· 9.8Potential buffer overflow in psd-tools
Potential buffer overflow in psd-tools
CVE-2018-1000164High· 7.5Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers